© Copyright Lenovo 2017
Chapter 7: Access Control Lists
129
Rate Limiting Behavior
Because
ACL
logging
can
be
CPU
‐
intensive,
logging
is
rate
‐
limited.
By
default,
the
switch
will
log
only
10
matching
packets
per
second.
This
pool
is
shared
by
all
log
‐
enabled
ACLs.
The
global
rate
limit
can
be
changed
as
follows:
Where
the
limit
is
specified
in
packets
per
second.
Log Interval
For
each
log
‐
enabled
ACL,
the
first
packet
that
matches
the
ACL
initiates
an
immediate
message
in
the
system
log.
Beyond
that,
additional
matches
are
subject
to
the
log
interval.
By
default,
the
switch
will
buffer
ACL
log
messages
for
a
period
of
300
seconds.
At
the
end
of
that
interval,
all
messages
in
the
buffer
are
written
to
the
system
log.
The
global
interval
value
can
be
changed
as
follows:
Where
the
interval
rate
is
specified
in
seconds.
In
any
given
interval,
packets
that
have
identical
log
information
are
condensed
into
a
single
message.
However,
the
packet
count
shown
in
the
ACL
log
message
represents
only
the
logged
messages,
which
due
to
rate
‐
limiting,
may
be
significantly
less
than
the
number
of
packets
actually
matched
by
the
ACL.
Also,
the
switch
is
limited
to
64
different
ACL
log
messages
in
any
interval.
Once
the
threshold
is
reached,
the
oldest
message
will
be
discarded
in
favor
of
the
new
message,
and
an
overflow
message
will
be
added
to
the
system
log.
ACL Logging Limitations
ACL
logging
reserves
packet
queue
1
for
internal
use.
Features
that
allow
remapping
packet
queues
(such
as
CoPP)
may
not
behave
as
expected
if
other
packet
flows
are
reconfigured
to
use
queue
1.
CN 4093(config)#
access-control log rate-limit
<1
‐
1000>
CN 4093(config)#
access-control log interval
<5
‐
600>
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...